{"id":53878,"date":"2020-08-06T08:05:55","date_gmt":"2020-08-06T15:05:55","guid":{"rendered":"https:\/\/github.blog\/?p=53878"},"modified":"2022-02-04T10:33:22","modified_gmt":"2022-02-04T18:33:22","slug":"achieving-devsecops-maturity-with-a-developer-first-community-driven-approach","status":"publish","type":"post","link":"https:\/\/github.blog\/enterprise-software\/devsecops\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\/","title":{"rendered":"Achieving DevSecOps maturity with a developer-first, community-driven approach"},"content":{"rendered":"<p>GitHub has been rapidly evolving into a complete development platform over the past year and a half, with the addition of native CI\/CD capabilities using <a href=\"https:\/\/docs.github.com\/en\/actions\">GitHub Actions<\/a>. But did you know that you can implement DevSecOps natively in GitHub Enterprise, using <a href=\"https:\/\/github.com\/features\/security\/\">GitHub Advanced Security<\/a>? In this post, we will explore the OWASP <a href=\"https:\/\/owasp.org\/www-project-devsecops-maturity-model\/\">DevSecOps Maturity Model<\/a> (DSOMM) and demonstrate how you can achieve Level 1 maturity by implementing software composition analysis (SCA), static application security testing (SAST), dynamic application security testing (DAST), and secret scanning using GitHub-native capabilities within the developer workflow.<\/p>\n<p><script>{\"@context\":\"https:\/\/schema.org\",\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is DSOMM?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"OWASP created the DSOMM framework in order to show application security measures which can be applied when using DevOps strategies and how these can be prioritized. DSOMM strives to incrementally increase the effectiveness of a security program from Level 1 (least mature), to Level 4\u2014a fully implemented DevSecOps program built into your DevOps practices. \"}}]}<\/script><\/p>\n<h2 id=\"what-is-dsomm\"><a class=\"heading-link\" href=\"#what-is-dsomm\">What is DSOMM?<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h2>\n<p>Before we dig into the how, let\u2019s align on a definition of DSOMM.<\/p>\n<p>OWASP created the <a href=\"https:\/\/owasp.org\/www-project-devsecops-maturity-model\/\">DSOMM framework<\/a> in order to show <a href=\"https:\/\/resources.github.com\/whitepapers\/Application-security-guide\/\">application security<\/a> measures which can be applied when using DevOps strategies and how these can be prioritized. DSOMM strives to incrementally increase the effectiveness of a security program from Level 1 (least mature), to Level 4\u2014a fully implemented DevSecOps program built into your DevOps practices.<\/p>\n<p><b>There are four main evaluation criteria in DSOMM:\u00a0<\/b><\/p>\n<ul>\n<li><i>Static depth<\/i> &#8211; How comprehensive the static code scan that you are performing within the AppSec CI pipeline is.<\/li>\n<li><i>Dynamic depth<\/i> &#8211; How comprehensive the dynamic scan that is being run within the AppSec CI pipeline is.<\/li>\n<li><i>Intensity &#8211;<\/i> Your schedule frequency for the security scans running in AppSec CI pipeline.<\/li>\n<li><i style=\"font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Helvetica, Arial, sans-serif\">Consolidation &#8211; <\/i><span style=\"font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Helvetica, Arial, sans-serif\">Your remediation workflow for handling findings and process completeness.<\/span><\/li>\n<\/ul>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-full wp-image-53883\" src=\"https:\/\/github.blog\/wp-content\/uploads\/2020\/08\/dsomm-identification-of-the-degree-of-the-implementation.png?resize=1024%2C1066\" alt=\"Diagram showing DevSecOps Maturity Model\" width=\"1024\" height=\"1066\" srcset=\"https:\/\/github.blog\/wp-content\/uploads\/2020\/08\/dsomm-identification-of-the-degree-of-the-implementation.png?w=1264 1264w, https:\/\/github.blog\/wp-content\/uploads\/2020\/08\/dsomm-identification-of-the-degree-of-the-implementation.png?w=288 288w, https:\/\/github.blog\/wp-content\/uploads\/2020\/08\/dsomm-identification-of-the-degree-of-the-implementation.png?w=768 768w, https:\/\/github.blog\/wp-content\/uploads\/2020\/08\/dsomm-identification-of-the-degree-of-the-implementation.png?w=984 984w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/p>\n<h2 id=\"reaching-dsomm-level-1\"><a class=\"heading-link\" href=\"#reaching-dsomm-level-1\">Reaching DSOMM Level 1<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h2>\n<p>DSOMM has four maturity levels that define various aspects of your overall DevSecOps program. In a typical Level 1 program your practices could mirror the following: Level 1 calls for the execution of static analysis tools including secret scanning, SCA, and SAST without any changes to the tools or settings. DAST tooling is often run with its baseline settings. A well-planned program will increase the intensity linearly over time. The scans are run on your default branch once a week or month and reporting may be disjointed initially, but don&#8217;t worry\u2014we will begin to consolidate at Level 2.<\/p>\n<p>Beyond tool implementation, a few key requirements for DSOMM Level 1 are to:<\/p>\n<ol>\n<li>Never fail a build based on scan results. At this level, there will be false positives and we want to prevent the erosion of trust between our security practices and the development teams that own the remediation workflow.<\/li>\n<li>Start small with tool implementation and knowledge transfer to the broader engineering teams. It is critical that those teams have the expertise to run the tooling and analyze the results.<\/li>\n<\/ol>\n<p>Ensure that your tooling provides <i>immediate<\/i> feedback to developers so they can fix their issues as early in the SDLC as possible. This saves time and brain cycles for developers who often manage tool and task context switching throughout their sprint cycle.<\/p>\n<h2 id=\"implementing-dsomm-level-1-on-github\"><a class=\"heading-link\" href=\"#implementing-dsomm-level-1-on-github\">Implementing DSOMM Level 1 on GitHub<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h2>\n<p>Now that we\u2019re aligned on a few of the cultural best practices and maturity evaluation criteria of DSOMM, let\u2019s implement our tooling with Advanced Security. On GitHub, you can easily use native capabilities to achieve DSOMM Level 1. You can enable native SCA, SAST and secret scanning capabilities, without any changes to existing tools or configurations; and also run DAST tooling with its default settings.<\/p>\n<p><script>\n{\n\"@context\": \"https:\/\/schema.org\",\n\"@type\": \"VideoObject\",\n\"name\": \"Demo Days - Empowering developers with GitHub Advanced Security\",\n\"description\": \"Kevin Alwell, Solutions Engineer, uses GitHub\u2019s fully-integrated CI\/CD to enable native application security features. Dive into GitHub Actions, code scanning, software composition analysis, secret detection, and policy enforcement to achieve DevSecOps maturity.\",\n\"uploadDate\": \"2020-09-30T08:00:00+08:00\",\n\"embedUrl\": \"https:\/\/www.youtube.com\/embed\/G5YQJdOhaZM\",\n}\n<\/script><\/p>\n\n\t\t<div class=\"mod-vh position-relative\" style=\"height: 0; padding-bottom: calc((9 \/ 16)*100%);\">\n\t\t\t<iframe loading=\"lazy\" class=\"position-absolute top-0 left-0 width-full height-full\" src=\"https:\/\/www.youtube.com\/embed\/G5YQJdOhaZM?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent\" title=\"YouTube video player\" allow=\"accelerometer; clipboard-write; encrypted-media; gyroscope; picture-in-picture\" allowfullscreen=\"\" frameborder=\"0\"><\/iframe>\n\t\t<\/div>\n<p>To learn how to do it yourself, check out the in-depth demo in the video above. To follow this session along in your own environment, you&#8217;ll need Advanced Security enabled on your organization. I&#8217;ll walk through implementing:<\/p>\n<ul>\n<li><a href=\"https:\/\/github.blog\/2020-08-13-secure-at-every-step-a-guide-to-devsecops-shifting-left-and-gitops\/#what-is-devsecops-applying-devops-principles-to-security\">DevSecOps<\/a> automation and DevSecOps methodology<\/li>\n<li><a href=\"https:\/\/docs.github.com\/en\/github\/visualizing-repository-data-with-graphs\/about-the-dependency-graph\">Dependency graph<\/a>, <a href=\"https:\/\/docs.github.com\/en\/github\/managing-security-vulnerabilities\/about-alerts-for-vulnerable-dependencies\">Dependabot alerts<\/a>, and Dependabot <a href=\"https:\/\/docs.github.com\/en\/github\/managing-security-vulnerabilities\/configuring-github-dependabot-security-updates#about-github-dependabot-security-updates\">security updates<\/a> for SCA<\/li>\n<li><a href=\"https:\/\/docs.github.com\/en\/github\/finding-security-vulnerabilities-and-errors-in-your-code\/about-code-scanning\">Code scanning<\/a> for SAST<\/li>\n<li><a href=\"https:\/\/docs.github.com\/en\/github\/administering-a-repository\/about-secret-scanning\">Secret scanning<\/a> for private repositories<\/li>\n<li>Open source <a href=\"https:\/\/github.com\/zaproxy\/zaproxy\">OWASP ZAP<\/a> scans for DAST<\/li>\n<\/ul>\n<p>Once your development team is practicing DSOMM and has achieved Level 1, you can try to tackle maturing to Level 2 in six to 12 months. Let\u2019s do this! Please join our <a href=\"https:\/\/www.twitch.tv\/githubenterprise?utm_source=github&amp;utm_medium=blog&amp;utm_campaign=security_campaign_q1&amp;utm_content=DemoDaySecuringYourOrg\">GitHub Demo Day livestream<\/a> and stay tuned for future blog posts on DevSecOps.<\/p>\n<p>Questions? Contact your account management team or the <a href=\"https:\/\/enterprise.github.com\/contact\">GitHub Sales Team<\/a> to see how GitHub can help your engineering team build better, more secure software together.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>GitHub provides the security capabilities to achieve Level 1 of the OWASP DevSecOps Maturity Model. In this post, we explore the principles of DSOMM Level 1 and how you can implement secret scanning, SCA, SAST and DAST using native tooling on GitHub.<\/p>\n","protected":false},"author":1711,"featured_media":53898,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_gh_post_show_toc":"no","_gh_post_is_no_robots":"","_gh_post_is_featured":"no","_gh_post_is_excluded":"","_gh_post_is_unlisted":"","_gh_post_related_link_1":"","_gh_post_related_link_2":"","_gh_post_related_link_3":"","_gh_post_sq_img":"","_gh_post_sq_img_id":"","_gh_post_cta_title":"Get free access to GitHub Enterprise","_gh_post_cta_text":"Choose from two trial plans designed to help your business grow. ","_gh_post_cta_link":"https:\/\/github.com\/organizations\/enterprise_plan?ref_page=\/blog&ref_cta=Start%20a%20free%20enterprise%20trial&ref_loc=sidebar","_gh_post_cta_button":"Start a free trial","_gh_post_recirc_hide":"","_gh_post_recirc_col_1":"","_gh_post_recirc_col_2":"","_gh_post_recirc_col_3":"","_gh_post_recirc_col_4":"","_featured_video":"","_gh_post_additional_query_params":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"{title}\n\n{excerpt}\n\n{url}","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"_wpas_customize_per_network":false,"jetpack_post_was_ever_published":false,"_links_to":"","_links_to_target":""},"categories":[3318,3313],"tags":[],"coauthors":[2147],"class_list":["post-53878","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-devsecops","category-enterprise-software"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.4 (Yoast SEO v28.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Achieving DevSecOps Level 1 Maturity with GitHub Advanced Security<\/title>\n<meta name=\"description\" content=\"Achieve Level 1 of the OWASP DevSecOps Maturity Model with GitHub Advanced security. Explore the principles of DSOMM Level 1 and how you can implement secret scanning, SCA, SAST and DAST using native tooling on GitHub.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/github.blog\/enterprise-software\/devsecops\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Achieving DevSecOps maturity with a developer-first, community-driven approach\" \/>\n<meta property=\"og:description\" content=\"Achieve Level 1 of the OWASP DevSecOps Maturity Model with GitHub Advanced security. Explore the principles of DSOMM Level 1 and how you can implement secret scanning, SCA, SAST and DAST using native tooling on GitHub.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/github.blog\/enterprise-software\/devsecops\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\/\" \/>\n<meta property=\"og:site_name\" content=\"The GitHub Blog\" \/>\n<meta property=\"article:published_time\" content=\"2020-08-06T15:05:55+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-02-04T18:33:22+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/github.blog\/wp-content\/uploads\/2020\/08\/dsomm-identification-of-the-degree-of-the-implementation-1.png?fit=1024%2C1066\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"1066\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Kevin Alwell\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/github.blog\/wp-content\/uploads\/2020\/08\/dsomm-identification-of-the-degree-of-the-implementation-1.png?fit=1024%2C1066\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Kevin Alwell\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/github.blog\\\/enterprise-software\\\/devsecops\\\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/github.blog\\\/enterprise-software\\\/devsecops\\\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\\\/\"},\"author\":{\"name\":\"Kevin Alwell\",\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/e5d57a937b8911b1001a3a3b45fdc718\"},\"headline\":\"Achieving DevSecOps maturity with a developer-first, community-driven approach\",\"datePublished\":\"2020-08-06T15:05:55+00:00\",\"dateModified\":\"2022-02-04T18:33:22+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/github.blog\\\/enterprise-software\\\/devsecops\\\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\\\/\"},\"wordCount\":684,\"image\":{\"@id\":\"https:\\\/\\\/github.blog\\\/enterprise-software\\\/devsecops\\\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/89543629-28be8c80-d7cf-11ea-9996-fac2427a4719.png?fit=1200%2C630\",\"articleSection\":[\"DevSecOps\",\"Enterprise software\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/github.blog\\\/enterprise-software\\\/devsecops\\\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\\\/\",\"url\":\"https:\\\/\\\/github.blog\\\/enterprise-software\\\/devsecops\\\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\\\/\",\"name\":\"Achieving DevSecOps Level 1 Maturity with GitHub Advanced Security\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/github.blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/github.blog\\\/enterprise-software\\\/devsecops\\\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/github.blog\\\/enterprise-software\\\/devsecops\\\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/89543629-28be8c80-d7cf-11ea-9996-fac2427a4719.png?fit=1200%2C630\",\"datePublished\":\"2020-08-06T15:05:55+00:00\",\"dateModified\":\"2022-02-04T18:33:22+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/e5d57a937b8911b1001a3a3b45fdc718\"},\"description\":\"Achieve Level 1 of the OWASP DevSecOps Maturity Model with GitHub Advanced security. Explore the principles of DSOMM Level 1 and how you can implement secret scanning, SCA, SAST and DAST using native tooling on GitHub.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/github.blog\\\/enterprise-software\\\/devsecops\\\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/github.blog\\\/enterprise-software\\\/devsecops\\\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/github.blog\\\/enterprise-software\\\/devsecops\\\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\\\/#primaryimage\",\"url\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/89543629-28be8c80-d7cf-11ea-9996-fac2427a4719.png?fit=1200%2C630\",\"contentUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/89543629-28be8c80-d7cf-11ea-9996-fac2427a4719.png?fit=1200%2C630\",\"width\":1200,\"height\":630,\"caption\":\"defining devsecops, devops, and gitops\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/github.blog\\\/enterprise-software\\\/devsecops\\\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/github.blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Enterprise software\",\"item\":\"https:\\\/\\\/github.blog\\\/enterprise-software\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"DevSecOps\",\"item\":\"https:\\\/\\\/github.blog\\\/enterprise-software\\\/devsecops\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Achieving DevSecOps maturity with a developer-first, community-driven approach\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/github.blog\\\/#website\",\"url\":\"https:\\\/\\\/github.blog\\\/\",\"name\":\"The GitHub Blog\",\"description\":\"Updates, ideas, and inspiration from GitHub to help developers build and design software.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/github.blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/e5d57a937b8911b1001a3a3b45fdc718\",\"name\":\"Kevin Alwell\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/5b87c43694e81d8b1fa52d68817e84001d376ddfb581f287a2d7af8363d2acb4?s=96&d=mm&r=g07de429bf9b71482f9bff2740864ac8c\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/5b87c43694e81d8b1fa52d68817e84001d376ddfb581f287a2d7af8363d2acb4?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/5b87c43694e81d8b1fa52d68817e84001d376ddfb581f287a2d7af8363d2acb4?s=96&d=mm&r=g\",\"caption\":\"Kevin Alwell\"},\"url\":\"https:\\\/\\\/github.blog\\\/author\\\/alwellkevin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Achieving DevSecOps Level 1 Maturity with GitHub Advanced Security","description":"Achieve Level 1 of the OWASP DevSecOps Maturity Model with GitHub Advanced security. Explore the principles of DSOMM Level 1 and how you can implement secret scanning, SCA, SAST and DAST using native tooling on GitHub.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/github.blog\/enterprise-software\/devsecops\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\/","og_locale":"en_US","og_type":"article","og_title":"Achieving DevSecOps maturity with a developer-first, community-driven approach","og_description":"Achieve Level 1 of the OWASP DevSecOps Maturity Model with GitHub Advanced security. Explore the principles of DSOMM Level 1 and how you can implement secret scanning, SCA, SAST and DAST using native tooling on GitHub.","og_url":"https:\/\/github.blog\/enterprise-software\/devsecops\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\/","og_site_name":"The GitHub Blog","article_published_time":"2020-08-06T15:05:55+00:00","article_modified_time":"2022-02-04T18:33:22+00:00","og_image":[{"width":1024,"height":1066,"url":"https:\/\/github.blog\/wp-content\/uploads\/2020\/08\/dsomm-identification-of-the-degree-of-the-implementation-1.png?fit=1024%2C1066","type":"image\/png"}],"author":"Kevin Alwell","twitter_card":"summary_large_image","twitter_image":"https:\/\/github.blog\/wp-content\/uploads\/2020\/08\/dsomm-identification-of-the-degree-of-the-implementation-1.png?fit=1024%2C1066","twitter_misc":{"Written by":"Kevin Alwell","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/github.blog\/enterprise-software\/devsecops\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\/#article","isPartOf":{"@id":"https:\/\/github.blog\/enterprise-software\/devsecops\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\/"},"author":{"name":"Kevin Alwell","@id":"https:\/\/github.blog\/#\/schema\/person\/e5d57a937b8911b1001a3a3b45fdc718"},"headline":"Achieving DevSecOps maturity with a developer-first, community-driven approach","datePublished":"2020-08-06T15:05:55+00:00","dateModified":"2022-02-04T18:33:22+00:00","mainEntityOfPage":{"@id":"https:\/\/github.blog\/enterprise-software\/devsecops\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\/"},"wordCount":684,"image":{"@id":"https:\/\/github.blog\/enterprise-software\/devsecops\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\/#primaryimage"},"thumbnailUrl":"https:\/\/github.blog\/wp-content\/uploads\/2020\/08\/89543629-28be8c80-d7cf-11ea-9996-fac2427a4719.png?fit=1200%2C630","articleSection":["DevSecOps","Enterprise software"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/github.blog\/enterprise-software\/devsecops\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\/","url":"https:\/\/github.blog\/enterprise-software\/devsecops\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\/","name":"Achieving DevSecOps Level 1 Maturity with GitHub Advanced Security","isPartOf":{"@id":"https:\/\/github.blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/github.blog\/enterprise-software\/devsecops\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\/#primaryimage"},"image":{"@id":"https:\/\/github.blog\/enterprise-software\/devsecops\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\/#primaryimage"},"thumbnailUrl":"https:\/\/github.blog\/wp-content\/uploads\/2020\/08\/89543629-28be8c80-d7cf-11ea-9996-fac2427a4719.png?fit=1200%2C630","datePublished":"2020-08-06T15:05:55+00:00","dateModified":"2022-02-04T18:33:22+00:00","author":{"@id":"https:\/\/github.blog\/#\/schema\/person\/e5d57a937b8911b1001a3a3b45fdc718"},"description":"Achieve Level 1 of the OWASP DevSecOps Maturity Model with GitHub Advanced security. Explore the principles of DSOMM Level 1 and how you can implement secret scanning, SCA, SAST and DAST using native tooling on GitHub.","breadcrumb":{"@id":"https:\/\/github.blog\/enterprise-software\/devsecops\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/github.blog\/enterprise-software\/devsecops\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/github.blog\/enterprise-software\/devsecops\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\/#primaryimage","url":"https:\/\/github.blog\/wp-content\/uploads\/2020\/08\/89543629-28be8c80-d7cf-11ea-9996-fac2427a4719.png?fit=1200%2C630","contentUrl":"https:\/\/github.blog\/wp-content\/uploads\/2020\/08\/89543629-28be8c80-d7cf-11ea-9996-fac2427a4719.png?fit=1200%2C630","width":1200,"height":630,"caption":"defining devsecops, devops, and gitops"},{"@type":"BreadcrumbList","@id":"https:\/\/github.blog\/enterprise-software\/devsecops\/achieving-devsecops-maturity-with-a-developer-first-community-driven-approach\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/github.blog\/"},{"@type":"ListItem","position":2,"name":"Enterprise software","item":"https:\/\/github.blog\/enterprise-software\/"},{"@type":"ListItem","position":3,"name":"DevSecOps","item":"https:\/\/github.blog\/enterprise-software\/devsecops\/"},{"@type":"ListItem","position":4,"name":"Achieving DevSecOps maturity with a developer-first, community-driven approach"}]},{"@type":"WebSite","@id":"https:\/\/github.blog\/#website","url":"https:\/\/github.blog\/","name":"The GitHub Blog","description":"Updates, ideas, and inspiration from GitHub to help developers build and design software.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/github.blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/github.blog\/#\/schema\/person\/e5d57a937b8911b1001a3a3b45fdc718","name":"Kevin Alwell","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/5b87c43694e81d8b1fa52d68817e84001d376ddfb581f287a2d7af8363d2acb4?s=96&d=mm&r=g07de429bf9b71482f9bff2740864ac8c","url":"https:\/\/secure.gravatar.com\/avatar\/5b87c43694e81d8b1fa52d68817e84001d376ddfb581f287a2d7af8363d2acb4?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/5b87c43694e81d8b1fa52d68817e84001d376ddfb581f287a2d7af8363d2acb4?s=96&d=mm&r=g","caption":"Kevin Alwell"},"url":"https:\/\/github.blog\/author\/alwellkevin\/"}]}},"jetpack_publicize_connections":[],"jetpack_shortlink":"https:\/\/wp.me\/pamS32-e10","jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/github.blog\/wp-content\/uploads\/2020\/08\/89543629-28be8c80-d7cf-11ea-9996-fac2427a4719.png?fit=1200%2C630","_links":{"self":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/53878","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/users\/1711"}],"replies":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/comments?post=53878"}],"version-history":[{"count":30,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/53878\/revisions"}],"predecessor-version":[{"id":53904,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/53878\/revisions\/53904"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/media\/53898"}],"wp:attachment":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/media?parent=53878"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/categories?post=53878"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/tags?post=53878"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/coauthors?post=53878"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}